Cybersecurity guide for developing countries
While it is impossible to eliminate risk entirely, and difficult to anticipate all the emerging threats, it is
important to reduce the vulnerability of environments and resources that are to be protected, as it
certainly lies at the origin of many of the security problems.
The security policy should specify, among other things, the resources, structure, procedures, and plans
for defence and mitigation to ensure that operational, technological and information risks can be
controlled.
ISO 17799 proposes a code of practice for security management. It can be considered as a reference
for defining a security policy; as a checklist for analysing risk; as a security audit tool, whether for
purposes of certification or not; or as a communication hub for security. The standard can be
interpreted, and implemented, in various ways. Its value resides in the fact that it addresses the
organizational, human, legal and technological aspects of security at each of the different stages of
design, implementation and maintenance of security. The 2005 version of the standard
(ISO/IEC 17799:2005)4 emphasizes risk evaluation and analysis, management of assets and resources,
and incident management. This is indicative of the importance that is attached to the management
dimension of security.
Figure I.6 – To manage security, first define a security policy
The components
of a security policy
What to protect?
From whom? Against what are we protecting ourselves?
Why?
Organization of security
Assign responsibilities to the
competent individuals with the
necessary authority and
resources
What are the real risks?
Can they be tolerated?
Identify security targets for
each domain and component
of the information system
Define the threats and identify
vulnerabilities
What is the organization’s current security position?
What is the desired level of security?
Define security measures
Define security practices
What are the real constraints? What are the available
resources? How should they be deployed?
The effectiveness of a security policy should not be measured by the size of its budget; rather, it
depends on the risk-management policy, and on the quality of the risk analysis (Figure I.6). Among
the factors that determine the risk are the area of activity of an organization, its size, its image, system
sensitivity, the system environment and associated threats, and the degree to which the organization
depends on its information system.
4 The table of contents of the standard is given in Annex B to this guide.
12
Cybersecurity